- Job title
- IT Manager
- Sector
- Catering
- Organization type
- chain store
- Joined
- Jan 2023
- Message
- 40
We are a 20-person SaaS company providing HR and shift management software to enterprise clients in the US market. Next quarter, we're set to sign a prospective enterprise client worth $80,000 annually, but they require an independent third-party security audit report from us.
We got quotes from two cybersecurity firms. The first quoted $1,500 and a 2-day turnaround for an automated vulnerability scan and report. The second quoted $6,500 and 10 business days for a manual penetration test.
There's nearly a 4x price and timeline difference. What exactly is the difference in technical depth and scope between these two? Will a vulnerability scan suffice for our prospective client, or do enterprise security reviews strictly require a pen test?